CATEGORY
Authentication 2,312 crates
Data as of 2026-07-25 (crates.io database dump, timestamp 2026-07-25T02:00:36Z). Source: crates.io · db-dump.tar.gz · methodology & corrections.
purwa-authSession and token authentication for Purwa — tower-sessions, axum-login, Argon2id81MIT
ssign-coreThe Certum SimplySign cloud-signing pipeline behind ssign: OAuth login, card/cert fetch, remote signature, and local…81MIT
rust-bottleRust implementation of Bottle protocol - layered message containers with encryption and signatures79MIT
auths-receiptsPortfolio 1 — accountability & dispute: the receipts/dispute-evidence MCP server, the non-custodial escrow MCP server, and the…79Apache-2.0
rok-acl-macrosProc-macro guards #[require_permission] and #[require_role] for rok-acl79MIT
hessra-cap-schemaPrincipal schema definitions for the Hessra capability engine78Apache-2.0
openauth-passkeyServer-side passkey plugin for OpenAuth.78MIT
cortexai-encryptionAt-rest encryption for sensitive data in Cortex: AES-GCM and ChaCha20-Poly130577Apache-2.0
openinternetcryptographykeysA Simple Standard Cryptography-Suite For Web 3.20, offering cryptographic abstraction (Generic Signing/Verifying, Generic…77Apache-2.0 OR MIT
cntm-nucleusNucleus authentication SDK for Rust.77MIT
getmyidRust client library for whoami Identity-by-PID daemon77MIT OR Apache-2.0
worker_jwtJWT generation for wasm runtimes (Cloudflare Workers, Deno, browsers) backed by the Web Crypto API77MIT
easy-auth-sdkA simple JWT-based authentication SDK with RBAC support77Apache-2.0
f8s-coreProtocol, crypto, invites, envelopes, and quarantine mailbox state for f8s.77MIT
nostr-bbs-auth-workerAuth Worker: WebAuthn + NIP-98 + pod provisioning (nostr-bbs)77AGPL-3.0-only
ch-authAuthentication and session primitives with explicit security policies77SUL-1.0
tana-authAuthentication and JWT utilities for Tana with Ed25519 signatures76MIT OR Apache-2.0
tokio-oidc-verifierServer-side OIDC bearer-token verification on tokio: discovery, JWKS fetch, local JWT verification with background refresh.76MIT OR Apache-2.0
phantom-secrets-vaultSecret vault backends for Phantom Secrets — OS keychain and encrypted file76MIT
kovra-native-macosmacOS LocalAuthentication (Touch ID) Confirmer for kovra (free core, [host]-validated).75BUSL-1.1
armoireA cross-platform library for working with desktop secrets.75MIT
openauth-oauth-providerOAuth 2.1 and OpenID Connect provider support for OpenAuth.75MIT
rustauth-cliCommand-line tools for RustAuth.75MIT
reqwest-negotiateKerberos/SPNEGO Negotiate authentication for reqwest74MIT OR Apache-2.0
tauri-plugin-social-authSocial auth mobile plugin for Tauri74MIT OR Apache-2.0
proton-coreUnofficial pure-Rust Proton Mail SDK: SRP authentication, OpenPGP end-to-end crypto, and the mail API (transport, send/read,…74MIT
krb5-gssPure Rust Kerberos protocol engine and krb5 GSS-API mechanism (initiator), no FFI74Apache-2.0 OR MIT
scim-rsSCIM 2.0 types and helpers for Rust.73MIT
mildly-basic-authBasic auth with nicer UX.73MIT OR Apache-2.0
axess-macrosAuth guard macros for axess: require_authn!, require_partial_authn!, require_authz! for Axum handlers.73MIT OR Apache-2.0
edgesentry-rsTamper-evident immutable audit trace: signing, verification, ingestion and CLI72MIT OR Apache-2.0
stellar-agent-windows-identityWindows account-SID lookup and DPAPI protect/unprotect. Safe wrappers isolating Win32 FFI from the unsafe-free core crate.72Apache-2.0
rustauth-axumAxum integration for RustAuth.72MIT
clickup_v2A comprehensive Rust client library and CLI for ClickUp API v2 with OAuth2 authentication, task management, and custom fields…71MIT
crissyCSRF protection middleware for Axum71MIT OR Apache-2.0
spherenet-badge-interfaceBadge program for on-chain attestations71Apache-2.0
lanyard-ssh-agentA resilient switching proxy for SSH agents71MIT OR Apache-2.0
propel-sdkDEPRECATED: use `propel` instead. This crate has been merged into the `propel` crate.70MIT OR Apache-2.0
rs-tenantMulti-tenant RBAC authorization engine for Rust70MIT OR Apache-2.0
openauth-redisRedis integrations for OpenAuth.70MIT
rust-crypto-utilsMemory-safe cryptographic utilities for secure key handling, encryption, and post-quantum readiness69MIT
sanctum-aiRust SDK for SanctumAI — credential management for AI agents69MIT
codex-oauthOAuth login for OpenAI Codex (ChatGPT account)69MIT
api-key-managerAgent-driven macOS Keychain CLI for API keys. Zero human friction.69MIT
authzen-rsA Rust SDK for the OpenID AuthZEN Authorization API 1.068MIT
frame-identityMulti-modal biometric identity verification for AI systems68MIT
libauthcekunitSuper robust CSRF token extractor with configurable retry, logging, and strict validation68MIT
ingress-aiShared AI-facing types for Gatewarden advisory workflows.68AGPL-3.0-only
hyperion-vpn-coreCore protocol for Hyperion VPN: SPA knock crypto, Noise IKpsk2 transport, yamux multiplexing, pooled client, and relay68AGPL-3.0-only
hyperion-vpn-cli-commonShared CLI plumbing for the Hyperion VPN binaries: config paths, daemon control, and secret handling68AGPL-3.0-only
sshpassxA secure, drop-in Rust replacement for sshpass with macOS Keychain and 1Password integration67MIT
kovra-agentkovra governed ssh-agent — serves signatures from vault-held keys under the sensitivity policy, keys never leave the vault.67BUSL-1.1
pow-captcha-axumEmbeddable axum routes for pow-captcha-server.67MIT
broadcast-authShared multi-scheme HTTP/RTSP auth: Basic/Digest (RFC 7235, RFC 2326 §14) via http-auth, Bearer (RFC 6750); one Credentials model…67MIT OR Apache-2.0
kpx-cliCommand-line KeePassXC browser integration client built on the kpx crate66MIT
permitheusFast hierarchical permission system with inheritance, delegation, and conflict resolution66MIT OR Apache-2.0
nsec-tree-rsDeterministic Nostr sub-identity derivation — Rust port of nsec-tree. HMAC-based one-way key hierarchy with Schnorr linkage…66MIT
actix-jwtFull-featured JWT authentication middleware for actix-web: login, logout, refresh, token rotation, cookie management, RSA/HMAC,…66MIT
secretx-k8sKubernetes Secret backend for secretx.66MIT
badgedA polkit authentication agent for Linux window managers64MIT
simple-srpSimplify usage of srp crate64Unlicense
authx-dashboardEmbedded admin dashboard for authx-rs64MIT
snowfinchAuthentication and sessions for Rust tower/axum servers.64MIT
attestation_verifierMinimal Intel TDX quote verification crate for raw quotes, hex, or wrapped TDX JSON payloads63MIT
aegis-protocol-tokenAegis Capability Token primitives for the experimental Aegis secure binary protocol.63MIT OR Apache-2.0
device-fingerprintCollect hardware information to generate a unique device fingerprint; Windows systems only.63MIT
authx-cliauthx command-line interface — serve, migrate, and manage users63MIT
revenant-sign-coreCross-platform client library for ARX CoSign / DocuSign Signature Appliance electronic signatures via the OASIS DSS SOAP API63Apache-2.0
nm-openvpn-ssoNetworkManager VPN plugin for OpenVPN with SSO/OAuth authentication62MIT
arcly-http-identityCIAM building-block engine for arcly-http: identity store traits, password hashing, MFA (TOTP), passwordless & account lifecycle,…62MIT
auth-payload-rsA global payload library that contains the common authentiation payload from providers like Google, github, and facebook62MIT
tibet-coreTIBET: Time-Intent-Based Event Tokens — forward-only causal substrate for AI provenance. OSAPI-pair with jis-core (identity +…61MIT OR Apache-2.0
ubl-authDID-first Ed25519 JWT/JWKS verification for OIDC-style flows. Enforces alg=EdDSA, checks exp/nbf/iat, JWKS cache.61MIT
kunobi-authAuthentication framework for Kunobi services — OIDC login, JWT validation, token management61Apache-2.0
quantumapiOfficial Rust SDK for QuantumAPI - European quantum-safe encryption and identity platform61MIT
tapwardenSSH agent backed by Bitwarden Secrets Manager with per-use biometric authorization61MIT
nexara-learning-jsonlJSONL usage signal store for Nexara learning60MIT
nexara-compat-qwenQwen-family compatibility helpers for Nexara60MIT
avl-authAVL Auth - Identity and Access Management for AVL Cloud Platform59MIT OR Apache-2.0
policy-coreCompile-time policy enforcement and taint tracking framework for Rust59MIT
sudo-proxyPrivileged command execution proxy with human approval via pkexec or sudo59MIT
nexara-learning-memoryIn-memory usage signal store for Nexara learning59MIT
nexara-learning-sledSled usage signal store for Nexara learning59MIT
nexara-serverStandalone HTTP server for Nexara tools and skill administration59MIT
signedshot-validatorValidator for SignedShot media authenticity proofs58MIT
firebase-rust-sdkUnofficial Rust port of Firebase C++ SDK58MIT
apohara-sealchain-coreCore engine for apohara-sealchain: apohara-seal-v1 receipts (JCS, layers, seal/verify)58MIT OR Apache-2.0
avl-secretsAVL Secrets - Secure secrets management for AVL Cloud Platform58MIT OR Apache-2.0
robopotatoLightweight inter-agent trust and shared state server for AI agent swarms58MIT
hessra-capHessra capability engine with default policy backend58Apache-2.0
pleme-auth-tokenspleme-auth-tokens library58MIT
krb5-rsPure Rust Kerberos V5: GSSAPI, SPNEGO, PKINIT. No C FFI, no system krb5 dependency.57Apache-2.0
paseto-rsA minimal, learning-focused PASETO v4 implementation in Rust57MIT
keystone-corePortable identity, signed social graph, and P2P transport primitives for the Keystone protocol57MIT
garrisonGarrison - 面向 Rust 生态的一站式身份认证鉴权框架57Apache-2.0
rs-authComposable authentication for Rust with Axum and Postgres.56MIT OR Apache-2.0
fdkeyFDKEY verification primitives for MCP servers and HTTP backends — gate AI-agent access behind LLM-only puzzles.56MIT
genotpSecure HOTP/TOTP library implementing RFC 4226 and RFC 623856MIT
codletCore authentication primitives for codlet: code policy, generation, normalization, keyed lookup derivation, lifecycle state…56Apache-2.0
reauth-sdkRust SDK for Reauth authentication55MIT
pleme-auth-sessionspleme-auth-sessions library55MIT
pleme-auth-validatorsNIST 2025 compliant password and field validation for authentication55MIT
pleme-auth-mfaMulti-factor authentication (TOTP + backup codes) for authentication services55MIT
zlicenser-serverServer library for the zlicenser hardware-bound software licensing framework.55Apache-2.0
wae-authenticationWAE Authentication - 认证服务模块,支持 JWT、OAuth2、TOTP、SAML54MIT
sarhash-coreA modular library for password hashing (Argon2) and strength verification (zxcvbn).54MIT
dig-accountThe DIG Network user Account: the fat, strictly-logical crate for everything an account does — the Account+Profile object model,…54GPL-2.0-only
reallyme-joseJOSE, JWT, JWS, and JWE helpers for ReallyMe identity.54Apache-2.0
oxitokenFastest and most secure JWT encoding/validation library for Rust. Fully supports custom header/claims structs, an extendable…53Apache-2.0 WITH LLVM-exception
kurbu5-kadm5-rsSafe, idiomatic Rust API for writing MIT Kerberos KADM5_AUTH and KADM5_HOOK plugin modules53BSD-2-Clause
pookieLoad cookies from web browsers53(Apache-2.0 OR BSL-1.0 OR Zlib) AND MIT
enfinitos-sdk-auditorEnfinitOS Auditor / Verifier SDK (Rust) — cryptographic verification library that regulators, auditors, courts, and third parties…53MIT
f8s-cliAgent-facing CLI for secure f8s mailbox threads.53MIT
nexara-policyDeterministic one-line policy authoring and simulation for Nexara53MIT
hsh-backend-awslcFIPS 140-3 routing layer for the `hsh` password-hashing crate. Wraps aws-lc-rs' PBKDF2-HMAC-SHA-256/512 derive functions, which…52MIT OR Apache-2.0
cyphr-storageStorage backends for Cyphr identity protocol52non-standard
cheers-coreContract surface for cheers — identity types, error hierarchy, CredentialStore, and the keyless TokenMinter/TokenVerifier traits.…52MIT OR Apache-2.0
secretx-memIn-process memory backend for secretx.51MIT
mcp-authorizationType-state authorization for MCP tool servers — compile-time proof that auth checks cannot be skipped51MIT
cloudconvert-sdkAsync Rust SDK primitives for the CloudConvert API v2.51MIT
arbitSecurity proxy for MCP (Model Context Protocol) — auth, rate limiting, payload filtering, and audit logging between AI agents and…51MIT
agenttrustidAgentTrust ID SDK — runtime authorization, opaque agent tokens, and Guardian checks for AI agents51Apache-2.0
crab-jwksMinimal JWT/JWKS library for Rust with RS256 support50MIT
aliyun-dypnsRust SDK for Alibaba Cloud Phone Number Verification Service (DYPNS)50MIT
gwafAI-native WAF for self-hosted apps with deterministic enforcement and reviewable policy workflows.50AGPL-3.0-only
spherenet-badge-clientBadge program for on-chain attestations50Apache-2.0
nowhub-plugin-rustRust SDK surface for Nowhub pay-plugin authorization checks49MIT
surreal-casbin-adapterA SurrealDB adapter for casbin-rs - an authorization library that supports access control models like ACL, RBAC, ABAC and more49Apache-2.0
ruvector-securitySecurity utilities for RuVector - authentication, path validation, rate limiting49Apache-2.0
mtls-actixActix-web middleware for mTLS authentication with IP whitelisting49GPL-3.0
hasp-backend-aws-smaws-sm:// backend for hasp — AWS Secrets Manager SDK client.49MIT OR Apache-2.0
hasp-backend-azure-kvazure-kv:// backend for hasp — Azure Key Vault REST client.49MIT OR Apache-2.0
hasp-backend-vaultvault:// backend for hasp — HashiCorp Vault KV HTTP client.49MIT OR Apache-2.0
openauth-fredFred-backed Redis and Valkey integrations for OpenAuth.49MIT
diegoPure Rust Active Directory security diagnostic agent. AS-REP Roasting, Kerberoasting, LDAP enumeration, OPSEC-friendly with…49MIT
mcp-governance-policyGovernance Policy MCP server for ADK-Rust Enterprise — policy evaluation, approvals, simulation, and audit evidence48Apache-2.0
no-way-jose-aes-cbc-hsAES-CBC + HMAC-SHA JWE content encryption for no-way-jose48Apache-2.0
no-way-jose-aes-kwAES Key Wrap (A128KW, A192KW, A256KW) JWE key management for no-way-jose48Apache-2.0
kamu-snap-crypto-actixactix-web inbound-verify middleware for kamu-snap-crypto SNAP BI signatures48MIT OR Apache-2.0
kamu-snap-crypto-axumaxum/tower inbound-verify layer for kamu-snap-crypto SNAP BI signatures48MIT OR Apache-2.0
archergate-licenseLicense management SDK for indie software developers — desktop apps, creative tools, game assets, and plugins48MIT
axum-security-oauth2A minimal OAuth2 client library, part of the axum-security workspace48MIT
hessra-clientHTTP client for Hessra authorization services48Apache-2.0
openapi-cli-rsCLI client for Openapi.com APIs48MIT
hasp-backend-aws-ssmaws-ssm:// backend for hasp — AWS SSM Parameter Store SDK client.48MIT OR Apache-2.0
hasp-backend-bwbw:// backend for hasp — Bitwarden CLI subprocess wrapper.48MIT OR Apache-2.0
hasp-backend-gcp-smgcp-sm:// backend for hasp — Google Cloud Secret Manager REST client.48MIT OR Apache-2.0
hasp-backend-opop:// backend for hasp — 1Password CLI subprocess wrapper.48MIT OR Apache-2.0
no-way-jose-aes-gcm-kwAES-GCM Key Wrap (A128GCMKW, A192GCMKW, A256GCMKW) JWE key management for no-way-jose47Apache-2.0
no-way-jose-aes-gcmAES-GCM JWE content encryption (A128GCM, A192GCM, A256GCM) for no-way-jose47Apache-2.0
no-way-jose-ecdh-esECDH-ES JWE key agreement (P-256, P-384, X25519) for no-way-jose47Apache-2.0
rust-saas-boilerplateProduction-grade Rust SaaS boilerplate - A complete starter template for building SaaS applications with authentication, user…47MIT
vaid-mintVAID reference mint (Rust): mint a root VAID and mint attenuated child VAIDs (scope/capability-contained delegation) over the…47Apache-2.0
openauth-axumAxum integration for OpenAuth.47MIT
openauth-cliCommand-line tools for OpenAuth.47MIT
axessModular authentication and authorization for Axum. Typed session state machine,
multi-factor authentication (password, TOTP,…47MIT OR Apache-2.0
no-way-jose-eddsaEdDSA (Ed25519) JWS algorithm for no-way-jose46Apache-2.0
no-way-jose-graviolaGraviola crypto backend for no-way-jose (HMAC, ECDSA, EdDSA, RSA, AES-GCM)46Apache-2.0
no-way-jose-hmacHMAC-SHA JWS algorithms (HS256, HS384, HS512) for no-way-jose46Apache-2.0
clove1gkModular authentication & authorization middleware for Rust — JWT pipeline with Axum and Actix-web support.46MIT
spiffe-rsRust port of spiffe-go with SPIFFE IDs, bundles, SVIDs, Workload API client, federation helpers, and rustls-based SPIFFE TLS…46Apache-2.0
webgates-axumAxum transport adapter for webgates authentication and authorization.46MIT
reqwest-kerberosKerberos/SPNEGO authentication for reqwest via Windows SSPI or Linux GSSAPI45MIT
no-way-jose-ecdsaECDSA JWS algorithms (ES256, ES384, ES512) for no-way-jose45Apache-2.0
karuAn embeddable policy engine focusing on structural pattern matching over arbitrary JSON data45MIT
no-way-jose-claimsJWT registered claims and composable validators for no-way-jose45Apache-2.0
no-way-jose-pbes2PBES2 password-based JWE key management for no-way-jose45Apache-2.0
no-way-jose-rsaRSA JWS/JWE algorithms (RS256, PS256, RSA-OAEP, etc.) for no-way-jose45Apache-2.0
no-way-jose-aws-lcaws-lc-rs crypto backend for no-way-jose (HMAC, ECDSA, EdDSA, RSA, AES-GCM)45Apache-2.0
atomic-lti-tool-axumLTI Tool related functionality for Axum45MIT OR Apache-2.0
wechat-backend-authA stateless WeChat OAuth client for backend API developers45MIT OR Apache-2.0
simple-oauthSimple OAuth2 login and authorization45MIT OR Apache-2.0
claude_authAnthropic OAuth token refresh transport — Layer * standalone primitive.45MIT
selepassA Rust crate for password verification and secure access layers.45MIT
dyolo-kya-redisRedis-backed RevocationStore and NonceStore for dyolo-kya production deployments44MIT OR Apache-2.0
keepass-rsPlatform-independent KeePass database library supporting KDB and KDBX (3.1, 4.0) file formats44MIT OR MulanPSL-2.0
tork-governanceOn-device AI governance SDK - PII detection, redaction, and cryptographic receipts44MIT
a1-aiA1 — The cryptographic identity and authorization layer that turns anonymous AI agents into accountable, verifiable entities. One…44MIT OR Apache-2.0
rune-axum-basicauthHTTP Basic authentication extractor and middleware layer for Axum with constant-time credential comparison43MIT
llm-config-rbacRole-Based Access Control (RBAC) system with fine-grained permissions, namespace isolation, and policy enforcement43Apache-2.0
oriko-coreVoudo Oriko core utilities - database, auth, and encryption43MIT
hymmalmLicensing client for license-management.com: JWS-signed license verification, trial bootstrap, activation and offline cache.…43MIT
aauthRust implementation of the AAuth authorization protocol43MIT OR Apache-2.0
xposedornotRust client library for the XposedOrNot data breach API42MIT
mere-identityIdentity management for the Mere browser — master Ed25519 keypair, OS-keychain integration, per-protocol identity derivation.42MIT OR Apache-2.0
verkle_pqQuantum-resistant Verkle tree library built on quilibrium-verkle with CRYSTALS-Dilithium3 (ML-DSA-65) post-quantum signatures and…42MIT
sigshareOpenID Shared Signals (SSF/CAEP/RISC) and Security Event Tokens for Rust42MIT OR Apache-2.0
claude-authorizeAutomates the OAuth Authorize button click for `claude login`42MIT OR Apache-2.0
sutegi-authThe sutegi user system: PBKDF2 password hashing (PHC strings), a Users store over any ORM backend, signed-cookie login sessions…42MIT
use-authnAuthentication metadata primitives for RustUse41MIT OR Apache-2.0
tongbal-oauthChzzk OAuth 2.0 client41MIT OR Apache-2.0
mc_headless_authHeadless Minecraft Server Authentication41MIT
idprova-cliIDProva CLI — manage agent identities, delegation tokens, and receipts41Apache-2.0
salvo-express-sessionExpress-session compatible session middleware for Salvo, with connect-redis support41MIT OR Apache-2.0
auth-middleware-pkgJWT authentication middleware for Axum with token validation and role-based access control41MIT OR Apache-2.0
kya-validatorRust core KYA (Know Your Agent) validator with Python bindings, TEE support, and blockchain integration41MPL-2.0
flowerpasswordFlower Password implementation for Rust - Deterministic password generator using HMAC-MD541MIT
axum-security-oidcA minimal OpenID Connect client library, part of the axum-security workspace41MIT
acls-rsAlgebraically-correct permissions system with RBAC, ABAC, and temporal support40MIT OR Apache-2.0
intentguard-cpiCPI helpers for IntentGuard — Solana 2FA protocol40MIT